The CMMC program rule (32 CFR part 170) has been in effect since December 16, 2024, and it sets specific rules for the Plan of Action and Milestones (POA&M). The POA&M is easy to misread in both directions: as a free pass, or as proof that any open item means automatic failure. Both readings are wrong.
A POA&M is a structured remediation plan with rules, timelines, and real consequences if you get it wrong. This guide breaks down POA&M requirements for CMMC Level 2: what the rule allows, what a credible entry contains, the mistakes that put Conditional status at risk, and how to manage POA&Ms without drowning in spreadsheets.
What is a POA&M, and how does it fit into CMMC?
A Plan of Action and Milestones identifies security weaknesses in your environment, maps them to specific NIST SP 800-171 controls, and lays out a concrete plan with milestones, responsible parties, and deadlines to remediate each gap.
In CMMC, a POA&M lets an Organization Seeking Assessment reach a Conditional CMMC Status, Conditional Level 2 (Self) or Conditional Level 2 (C3PAO), while it remediates a limited set of requirements scored NOT MET (32 CFR 170.21(a)). A POA&M is not permitted at any time for Level 1 (32 CFR 170.21(a)(1)). This is not a free pass. It is a structured, time-bound commitment.
Under CMMC, POA&M items carry scoring consequences, a 180-day closeout deadline, and specific exclusions on which requirements can appear on a POA&M at all (32 CFR 170.21).
What CMMC allows, and doesn't allow, on a POA&M
Not every failed control qualifies for POA&M treatment. CMMC Level 2 separates requirements that can be remediated after the assessment from those that must be MET at the time of the assessment.
Controls eligible for a POA&M
For CMMC Level 2, a requirement scored NOT MET may be carried on a POA&M only when all three conditions in 32 CFR 170.21(a)(2) hold: the assessment score is at least 80% of the 110 Level 2 requirements (88 points or more); every requirement on the POA&M is worth 1 point in the CMMC Scoring Methodology (32 CFR 170.24), with one exception, SC.L2-3.13.11 CUI Encryption, which may be included when encryption is employed but is not FIPS-validated; and none of the six requirements listed below is on it. The closing of the POA&M must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date, or the Conditional status expires (32 CFR 170.21(b)).
Controls that cannot be on a POA&M
Any requirement worth 3 or 5 points must be MET at the time of assessment, apart from the SC.L2-3.13.11 case above. Six more requirements may never be on a POA&M, whatever their point value (32 CFR 170.21(a)(2)(iii)): AC.L2-3.1.20 External Connections, AC.L2-3.1.22 Control Public Information, CA.L2-3.12.4 System Security Plan, PE.L2-3.10.3 Escort Visitors, PE.L2-3.10.4 Physical Access Logs, and PE.L2-3.10.5 Manage Physical Access.
Scoring implications: under the CMMC Scoring Methodology the maximum Level 2 score equals the number of Level 2 requirements, 110, and each requirement NOT MET subtracts its value (1, 3 or 5) from that maximum, which can produce a negative score (32 CFR 170.24(c)(2)). Requirements on a POA&M are NOT MET, so they count against the score until they are closed. A Level 2 self-assessment score is entered in the Supplier Performance Risk System (SPRS) (32 CFR 170.16(a)(1)(i)).
Before you decide what belongs on a POA&M, you need to know which controls you actually meet. A free 10-question gap check gives you a directional self-assessment (not an official SPRS score).
Run the free gap check →Anatomy of an effective POA&M entry
Each entry is a structured commitment. Here is what goes into a credible one.
- Weakness description: specific and measurable. Not "we need to improve access controls," but "AC.L2-3.1.3: CUI data flows are not restricted at the network boundary between the corporate VLAN and the CUI enclave."
- Control mapping: direct mapping to the NIST SP 800-171 control identifier and assessment objective.
- Responsible party: a named individual or role, not a department.
- Scheduled completion date: within the required closeout window and realistic given your resources.
- Resources required: budget, tools, personnel, and vendor support needed to close the gap.
- Risk assessment and interim mitigations: the residual risk while the gap exists and the compensating controls in place until remediation is complete.
What makes an entry credible
- Realistic timelines, not aspirational targets. A credible timeline accounts for procurement, implementation, testing, and validation.
- Evidence of progress, not just plans. Purchase orders, vendor contracts, partially deployed configurations, and test results all demonstrate commitment.
- Interim risk mitigations. If MFA is not fully deployed, what compensating controls protect those access points right now?
POA&M mistakes that put Conditional status at risk
- Using the POA&M as a dumping ground. A long POA&M means a long list of requirements scored NOT MET, and if they take the score below 88 of 110, Conditional status is not available at all (32 CFR 170.21(a)(2)(i)).
- No interim mitigations. An acknowledged weakness with no compensating control leaves the risk unaddressed for as long as the item stays open.
- Unrealistic timelines. Short deadlines on items that require procurement cycles and complex deployments are likely to be missed, and the 180-day closeout does not move (32 CFR 170.21(b)).
- Missing resource allocation. An item without a budget, assigned personnel, and identified tools is a plan without a foundation.
- Not tracking to closure. POA&M items that are created and then ignored drift, and a POA&M not closed out within 180 days ends the Conditional status (32 CFR 170.21(b)).
How AaaS platforms streamline POA&M management
A POA&M kept in a spreadsheet stays current only while someone remembers to update it: copies multiply and dates go stale. An Agent-as-a-Service (AaaS) platform built for CMMC turns POA&M upkeep from a manual tracking exercise into a plan re-issued every cycle, giving your team leverage rather than adding headcount.
- Gap identification and POA&M drafting. On a readiness subscription, the platform takes the gaps in your CMMC Level 2 Readiness Snapshot (your intake answers, plus measured findings from any cloud you connect) and drafts POA&M entries mapped to NIST SP 800-171 requirement IDs, each with a severity, a proposed owner, a proposed completion date and remediation steps, and with its 32 CFR 170.21 eligibility called out. The plan is marked as a draft for your designated executive to review, adjust and approve.
- Dates kept with every item. The closeout clock is unforgiving. Each POA&M item carries a proposed completion date, and the platform re-issues the POA&M on your tier's cycle; closing items inside 180 days stays your team's work and your team's decision.
- Linkage with your SSP. Your POA&M should align with your System Security Plan and control narratives. On a subscription, the platform builds both from the same readiness data in the same cycle, so they start from one set of gaps.
- Executive review. Each POA&M carries a status summary on its cover. Your Affirming Official, not the platform, decides what is approved and what is affirmed.
If your POA&M strategy today is a shared spreadsheet, start by finding out where you actually stand. Run the free gap check, then map your real posture with the $999 CMMC Level 2 Readiness Snapshot.
Source: 32 CFR 170.16, 170.21 and 170.24, as published in the CMMC Program final rule, 89 FR 83092 (Oct. 15, 2024); NIST SP 800-171 Rev. 2. This article is general guidance, not legal or compliance advice. Confirm the POA&M rules against the current eCFR text before you build your plan.